test: add unit tests for baseURL isolation logic

Add comprehensive tests for the resolveBaseURL utility function:
- Tests for user-provided API key scenarios
- Tests for server credential scenarios
- Edge case tests for empty strings and undefined values

This addresses the Copilot review suggestion to add test coverage
for the critical security fix.
This commit is contained in:
dayuan.jiang
2026-01-13 22:14:45 +09:00
parent d5774b336c
commit 9677737745
2 changed files with 163 additions and 1 deletions
+26
View File
@@ -62,6 +62,32 @@ const ANTHROPIC_BETA_HEADERS = {
"anthropic-beta": "fine-grained-tool-streaming-2025-05-14",
}
/**
* Resolve baseURL based on whether user is providing their own API key.
* When user provides their own API key, we should NOT fall back to server's
* baseURL environment variable - user credentials should only be sent to
* user-specified endpoints or official provider endpoints.
*
* @param userApiKey - User-provided API key (if any)
* @param userBaseUrl - User-provided base URL (if any)
* @param serverBaseUrl - Server's base URL from environment variable
* @param defaultBaseUrl - Provider's official/default base URL (optional)
* @returns The resolved base URL to use
*/
export function resolveBaseURL(
userApiKey: string | null | undefined,
userBaseUrl: string | null | undefined,
serverBaseUrl: string | undefined,
defaultBaseUrl?: string,
): string | undefined {
if (userApiKey) {
// User provides their own API key - only use user's baseUrl or default
return userBaseUrl || defaultBaseUrl || undefined
}
// No user API key - fall back to server config
return userBaseUrl || serverBaseUrl || defaultBaseUrl || undefined
}
/**
* Safely parse integer from environment variable with validation
*/
+137 -1
View File
@@ -1,5 +1,141 @@
import { describe, expect, it } from "vitest"
import { supportsImageInput, supportsPromptCaching } from "@/lib/ai-providers"
import {
resolveBaseURL,
supportsImageInput,
supportsPromptCaching,
} from "@/lib/ai-providers"
describe("resolveBaseURL", () => {
const SERVER_BASE_URL = "https://server-proxy.example.com"
const USER_BASE_URL = "https://user-proxy.example.com"
const DEFAULT_BASE_URL = "https://api.provider.com/v1"
const USER_API_KEY = "user-api-key-123"
describe("when user provides their own API key", () => {
it("uses user's baseUrl when provided", () => {
const result = resolveBaseURL(
USER_API_KEY,
USER_BASE_URL,
SERVER_BASE_URL,
DEFAULT_BASE_URL,
)
expect(result).toBe(USER_BASE_URL)
})
it("uses default baseUrl when user provides no baseUrl", () => {
const result = resolveBaseURL(
USER_API_KEY,
null,
SERVER_BASE_URL,
DEFAULT_BASE_URL,
)
expect(result).toBe(DEFAULT_BASE_URL)
})
it("returns undefined when user provides no baseUrl and no default exists", () => {
const result = resolveBaseURL(
USER_API_KEY,
null,
SERVER_BASE_URL,
undefined,
)
expect(result).toBeUndefined()
})
it("does NOT use server's baseUrl even when available", () => {
const result = resolveBaseURL(
USER_API_KEY,
undefined,
SERVER_BASE_URL,
undefined,
)
// Should NOT return SERVER_BASE_URL
expect(result).not.toBe(SERVER_BASE_URL)
expect(result).toBeUndefined()
})
it("prefers user's baseUrl over default", () => {
const result = resolveBaseURL(
USER_API_KEY,
USER_BASE_URL,
SERVER_BASE_URL,
DEFAULT_BASE_URL,
)
expect(result).toBe(USER_BASE_URL)
})
})
describe("when using server credentials (no user API key)", () => {
it("uses user's baseUrl when provided (overrides server)", () => {
const result = resolveBaseURL(
null,
USER_BASE_URL,
SERVER_BASE_URL,
DEFAULT_BASE_URL,
)
expect(result).toBe(USER_BASE_URL)
})
it("falls back to server's baseUrl when no user baseUrl", () => {
const result = resolveBaseURL(
null,
null,
SERVER_BASE_URL,
DEFAULT_BASE_URL,
)
expect(result).toBe(SERVER_BASE_URL)
})
it("falls back to default when no user or server baseUrl", () => {
const result = resolveBaseURL(
null,
null,
undefined,
DEFAULT_BASE_URL,
)
expect(result).toBe(DEFAULT_BASE_URL)
})
it("returns undefined when no baseUrl available anywhere", () => {
const result = resolveBaseURL(null, null, undefined, undefined)
expect(result).toBeUndefined()
})
it("handles undefined apiKey same as null", () => {
const result = resolveBaseURL(
undefined,
null,
SERVER_BASE_URL,
DEFAULT_BASE_URL,
)
expect(result).toBe(SERVER_BASE_URL)
})
})
describe("edge cases", () => {
it("handles empty string apiKey as falsy (uses server config)", () => {
const result = resolveBaseURL(
"",
null,
SERVER_BASE_URL,
DEFAULT_BASE_URL,
)
// Empty string is falsy, so should use server config
expect(result).toBe(SERVER_BASE_URL)
})
it("handles empty string baseUrl as falsy", () => {
const result = resolveBaseURL(
USER_API_KEY,
"",
SERVER_BASE_URL,
DEFAULT_BASE_URL,
)
// Empty string baseUrl is falsy, should fall back to default
expect(result).toBe(DEFAULT_BASE_URL)
})
})
})
describe("supportsPromptCaching", () => {
it("returns true for Claude models", () => {